Integer overflow in Linux kernel - CVE-2026-80710

 

Integer overflow in Linux kernel - CVE-2026-80710

Published: August 28, 2026


Vulnerability identifier: #VU146074
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-80710
CWE-ID: CWE-190
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to an integer overflow leading to an undersized allocation in dasd_eckd_check_device_format() when processing caller-controlled track ranges. A local user can provide a sufficiently large start and stop unit range to trigger a buffer overflow and cause a denial of service.

The issue occurs because the computed buffer size is truncated before allocation, while subsequent operations use the full untruncated track count.


Affected software

Linux kernel

How to mitigate CVE-2026-80710

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3

External References

Related Security Bulletins